Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1518.001 Security Software Discovery |
GroupAPT38 | APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system. |
| T1518.001 Security Software Discovery |
GroupBlackByte | BlackByte enumerated installed security products during operations. |
| T1518.001 Security Software Discovery |
GroupSideCopy | SideCopy uses a loader DLL file to collect AV product names from an infected host. |
| T1518.001 Security Software Discovery |
GroupKimsuky | Kimsuky has checked for the presence of antivirus software with |
| T1518.001 Security Software Discovery |
GroupPatchwork | Patchwork scanned the “Program Files” directories for a directory with the string “Total Security” (the installation path of the “360 Total Security” antivirus tool). |
| T1518.001 Security Software Discovery |
GroupMuddyWater | MuddyWater has used malware to check running processes against a hard-coded list of security tools often used by malware researchers. |
| T1518.001 Security Software Discovery |
GroupNaikon | Naikon uses commands such as |
| T1518.001 Security Software Discovery |
GroupGamaredon Group | Gamaredon Group has used PowerShell scripts to identify security software on the victim machine. |
| T1518.001 Security Software Discovery |
GroupTeamTNT | TeamTNT has searched for security products on infected machines. |
| T1518.001 Security Software Discovery |
GroupSidewinder | Sidewinder has used the Windows service |
| T1518.001 Security Software Discovery |
GroupRocke | Rocke used scripts which detected and uninstalled antivirus software. |
| T1518.001 Security Software Discovery |
GroupTA2541 | TA2541 has used tools to search victim systems for security products such as antivirus and firewall software. |
| T1518.001 Security Software Discovery |
GroupTropic Trooper | Tropic Trooper can search for anti-virus software running on the system. |
| T1518.001 Security Software Discovery |
GroupAquatic Panda | Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems. |
| T1518.001 Security Software Discovery |
GroupThe White Company | The White Company has checked for specific antivirus products on the target’s computer, including Kaspersky, Quick Heal, AVG, BitDefender, Avira, Sophos, Avast!, and ESET. |
| T1518.001 Security Software Discovery |
GroupTurla | Turla has obtained information on security software, including security logging information that may indicate whether their malware has been detected. |
| T1518.001 Security Software Discovery |
GroupStorm-0501 | Storm-0501 has detected endpoint security solutions using `sc query sense` and `sc query windefend`. |
| T1518.001 Security Software Discovery |
GroupMedusa Group | Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables. |
| T1518.001 Security Software Discovery |
GroupDarkhotel | Darkhotel has searched for anti-malware strings and anti-virus processes running on the system. |
| T1518.001 Security Software Discovery |
GroupWindshift | Windshift has used malware to identify installed AV and commonly used forensic and malware analysis tools. |
| T1518.001 Security Software Discovery |
GroupToddyCat | ToddyCat can determine is Kaspersky software is running on an endpoint by running `cmd /c wmic process where name="avp.exe"`. |
| T1518.001 Security Software Discovery |
GroupMalteiro | Malteiro collects the installed antivirus on the victim machine. |
| T1518.001 Security Software Discovery |
GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to check for anti-virus products. |
| T1518.001 Security Software Discovery |
GroupCobalt Group | Cobalt Group used a JavaScript backdoor that is capable of collecting a list of the security solutions installed on the victim's machine. |
| T1518.001 Security Software Discovery |
GroupWizard Spider | Wizard Spider has used WMI to identify anti-virus products installed on a victim's machine. |
| T1518.001 Security Software Discovery |
GroupPlay | Play has used the information-stealing tool Grixba to scan for anti-virus software. |
| T1518.001 Security Software Discovery |
GroupFIN8 | FIN8 has used Registry keys to detect and avoid executing in potential sandboxes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.